Vulnerabilities > Asus > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-11-14 | CVE-2019-15412 | Unspecified vulnerability in Asus Zenfone 4 Selfie Firmware The Asus ZenFone 4 Selfie Android device with a build fingerprint of asus/WW_Z01M/ASUS_Z01M_1:7.1.1/NMF26F/WW_71.50.395.57_20180913:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. | 4.6 |
2019-10-20 | CVE-2019-18216 | Unspecified vulnerability in Asus ROG Zephyrus M Gm501Gs Firmware The BIOS configuration design on ASUS ROG Zephyrus M GM501GS laptops with BIOS 313 relies on the main battery instead of using a CMOS battery, which reduces the value of a protection mechanism in which booting from a USB device is prohibited. low complexity asus | 6.8 |
2019-09-17 | CVE-2018-20336 | Classic Buffer Overflow vulnerability in Asus Asuswrt-Merlin 3.0.0.4.384.20308 An issue was discovered in ASUSWRT 3.0.0.4.384.20308. | 5.0 |
2019-08-29 | CVE-2019-11061 | Missing Authentication for Critical Function vulnerability in Asus Hg100 Firmware 1.05.12/4.00.06 A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself via http://[target]/smarthome/devicecontrol without any authentication. | 4.8 |
2019-06-24 | CVE-2017-17945 | Improper Certificate Validation vulnerability in Asus Hivivo and Vivobaby The ASUS HiVivo aspplication before 5.6.27 for ASUS Watch has Missing SSL Certificate Validation. | 6.4 |
2019-06-20 | CVE-2017-17944 | Improper Certificate Validation vulnerability in Asus Hivivo and Vivobaby The ASUS Vivobaby application before 1.1.09 for Android has Missing SSL Certificate Validation. | 6.4 |
2019-05-13 | CVE-2018-14713 | Use of Externally-Controlled Format String vulnerability in Asus Rt-Ac3200 Firmware 3.0.0.4.382.50010 Format string vulnerability in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to read arbitrary sections of memory and CPU registers via the "hook" URL parameter. | 5.5 |
2019-05-13 | CVE-2018-14712 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Asus Rt-Ac3200 Firmware 3.0.0.4.382.50010 Buffer overflow in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to inject system commands via the "hook" URL parameter. | 4.0 |
2019-05-13 | CVE-2018-14711 | Cross-Site Request Forgery (CSRF) vulnerability in Asus Rt-Ac3200 Firmware 3.0.0.4.382.50010 Missing cross-site request forgery protection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to cause state-changing actions with specially crafted URLs. | 4.3 |
2019-05-13 | CVE-2018-14710 | Cross-site Scripting vulnerability in Asus Rt-Ac3200 Firmware 3.0.0.4.382.50010 Cross-site scripting in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute JavaScript via the "hook" URL parameter. | 4.3 |